CVE-2022-29806 is a critical remote code execution vulnerability affecting ZoneMinder versions prior to 1.36.13. Attackers can exploit an invalid language setting, combined with the ability to create debug log files at arbitrary paths, to achieve full system compromise. With a CVSS score of 9.8 (CRITICAL) and high EPSS, this vulnerability poses a significant risk due to its network-based attack vector, low complexity, and complete impact on confidentiality, integrity, and availability. While not listed on CISA's KEV catalog, a Metasploit module exists, indicating readily available exploit code, despite a lack of broader community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.36.13CPE matchmatch criteria | cpe:2.3:a:zoneminder:zoneminder:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.